From the Director - 7 Key Elements for Making an InfoSec Program Operationally Effective
- Governance - Oversight
- Policy – The simple, brief, high level set of enterprise goals for InfoSec
- Architecture- A business architecture mapping InfoSec requirements against basic capabilities
- Awareness and Training – Making the enterprise aware of the first three elements
- Technology – The hardware and software infrastructure that embodies the goals of the policy, conforms to the architectural standards, and supports and amplifies the governance and training principles set forth
- Logging, auditing and reporting – The specific outputs and related management actions that allow the organization to check, at every relevant level, the working of the preceding elements
- Revitalization – The ongoing process of verifying the relevance and currency of the program
|
|
|